CVE-2020-24912
PHP vulnerability analysis and mitigation

Overview

A reflected cross-site scripting (XSS) vulnerability was discovered in QCubed, a PHP Model-View-Controller Rapid Application Development framework. The vulnerability, identified as CVE-2020-24912, affects all versions of QCubed including version 3.1.1. The issue was discovered in April 2020 and publicly disclosed in February 2021 (Full Disclosure, Tech Blog).

Technical details

The vulnerability exists in the profile.php file via the stQuery-parameter. The issue occurs because SQL output in profile.php is not properly sanitized. The vulnerability can be exploited in conjunction with SQL injection vulnerability (CVE-2020-24913), allowing attackers to output XSS payloads through SQL queries (Tech Blog).

Impact

The vulnerability allows unauthenticated attackers to steal sessions of authenticated users, potentially leading to unauthorized access to user accounts and sensitive information (Full Disclosure).

Exploitability

The vulnerability can be exploited remotely by unauthenticated attackers. A proof of concept exists demonstrating how the SQL output can be manipulated to inject XSS payloads using base64 encoded JavaScript (Tech Blog).

Mitigation and workarounds

QCubed released a patch that allows administrators to disable the profile functionality. The fix was delivered through a GitHub pull request (https://github.com/qcubed/qcubed/pull/1320/files) on May 1, 2020 (Full Disclosure).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management